MCP gateway with 10 tools for code analysis, architecture, package audit & security.
Dedotto dai trasporti dichiarati da questo annuncio (streamable-http). Un client che non compare qui non è escluso — semplicemente Forge non è in grado di confermarlo.
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Letto da un vero handshake MCP initialize → tools/list verso l’endpoint dichiarato. Nessuno strumento è stato invocato — tools/list è la chiamata di introspezione in sola lettura che il protocollo prevede a questo scopo. Riflette ciò che il server annunciava in quel momento; un endpoint ospitato non è vincolato ad alcuna versione e può cambiare senza preavviso.
https://zephex.dev/mcp10 strumenti · 582 msaudit_headersrischio di injectionAudit a public HTTPS URL the user deployed — security grade A–F, SSL, headers, cookies, health (ALIVE/DEGRADED/BROKEN), exposed secrets, tech stack. Read plain_summary first; only drill into security_headers or secrets if grade is poor. quick ~1–3s; scan_depth=deep for secret scan (~8–12s). 6 credi…Audit a public HTTPS URL the user deployed — security grade A–F, SSL, headers, cookies, health (ALIVE/DEGRADED/BROKEN), exposed secrets, tech stack. Read plain_summary first; only drill into security_headers or secrets if grade is poor. quick ~1–3s; scan_depth=deep for secret scan (~8–12s). 6 credi…
when user pastes a live URL — post-deploy check, is it secure, what framework, exposed keys. Blocks localhost/private IP…url: Links to undeclared domain: myapp.vercel.app| Parametro | Tipo | Descrizione |
|---|---|---|
| url* | string | Public https:// URL to audit — e.g. https://myapp.vercel.app or https://zephex.dev |
| path | string | Optional subpath (e.g. /checkout) — appended to url |
| scan_mode | string | quick=~1-3s (default); thorough=DNS+APIs+secrets ~5-12s |
| check_redirects | boolean | Follow and audit the full redirect chain (default: true) |
| check_ssl | boolean | Check SSL certificate validity, expiry, and protocol (default: true) |
| check_headers | boolean | Grade all security headers and return fix snippets when include_fix_snippets=true (default: true) |
| check_cookies | boolean | Check cookie Secure/HttpOnly/SameSite flags (default: true) |
| check_health | boolean | Site health: verdict, trust score, load time, page title (default: true) |
| check_tech | boolean | Tech stack: framework, hosting, CDN, third-party (default: true) |
| check_secrets | boolean | Secret scan: HTML/JS keys, exposed .env/.git, GraphQL (default: true; depth via scan_depth) |
| scan_depth | string | quick=light scan, 3 bundles (default); deep=full supply URL phase with JWT decode, source maps, verification (~8-12s) |
| check_apis | boolean | Probe /api/health and common API paths — adds ~1-2s (default: false) |
| check_network | boolean | HTTP network timing table — slow requests, API probes (default: true) |
| security_depth | string | basic=fast (default); full adds DNS SPF/DMARC/DKIM + HSTS preload lookup |
| timeout_ms | number | Max scan time in ms (default: 8000, max: 15000) |
| focus | string | Trim output layers (default: all) |
| include_fix_snippets | boolean | Include Nginx/Vercel/Next fix snippets — token-heavy (default: false) |
| probe_engine | string | fetch=HTTP only (default); browser=headless Chrome on Zephex servers for console errors + browser network (falls back to fetch with warning if unavailable) |
check_packageVerify a public registry package before the agent recommends, installs, or changes a dependency. ALWAYS call when the user says install, add a package, add a dependency, upgrade, bump, migrate, is this package safe, is this name real, check CVEs, vulnerability, deprecation, slopsquatting, supply-ch…Verify a public registry package before the agent recommends, installs, or changes a dependency. ALWAYS call when the user says install, add a package, add a dependency, upgrade, bump, migrate, is this package safe, is this name real, check CVEs, vulnerability, deprecation, slopsquatting, supply-ch…
| Parametro | Tipo | Descrizione |
|---|---|---|
| package* | string | Package name on the public registry — e.g. next, stripe, prisma, express, @supabase/supabase-js. |
| task | string | One goal per call: check=safe to add; security=CVEs for version; upgrade=version bump plan; migrate=major-version migration; debug=version-specific release clu… |
| version | string | Installed or pinned version. Pass for task=check|security so advisories are evaluated against the user's actual version. |
| from_version | string | Version being changed from. Pass for task=upgrade|migrate|debug so release notes and advisories are version-specific. |
| source | string | Optional. local = read pinned version from disk (stdio only). Prefer passing version/from_version directly. |
| ecosystem | string | Registry (default npm, auto-detected). Omit for next/stripe/prisma. |
| channel | string | INTERNAL: Zephex terminal CLI only. Agents must omit — returns richer fields than agent-safe JSON. |
| cli_depth | string | INTERNAL: CLI terminal depth. Agents must omit. |
check_testRun the project's real test suite and return structured health — the same engine as the terminal command zephex check test. Detects bun, vitest, jest, pytest, go test, and cargo. Parses JUnit plus lcov (not a regex over stdout). Returns summary, a plain card (what broke, why clusters, coverage, war…Run the project's real test suite and return structured health — the same engine as the terminal command zephex check test. Detects bun, vitest, jest, pytest, go test, and cargo. Parses JUnit plus lcov (not a regex over stdout). Returns summary, a plain card (what broke, why clusters, coverage, war…
| Parametro | Tipo | Descrizione |
|---|---|---|
| task | string | run = execute the suite (stores a session). detect = see runner, do not execute. failures|status|list|coverage|fix_prompt|why = read the last session (no re-ru… |
| path | string | Project folder. Local/stdio: omit to use the editor cwd (tests run on their machine), or pass the absolute folder. Hosted: public GitHub URL or inline_files —… |
| session_id | string | From a prior task=run (ts_*). Reuse for failures/status/list/why/fix_prompt so you do not re-run. Omit on stdio to read the last run on this machine. |
| file_filter | string | Substring or glob fragment to filter test_files (e.g. auth, handlers) |
| area | string | Scope to module/area name derived from test paths (e.g. proxy, auth, handlers) |
| question | string | Natural-language follow-up for task:why (e.g. "what failed in proxy?") |
| command | string | Override auto-detected test command |
| with_coverage | boolean | Collect lcov coverage (default true) |
| failed_only | boolean | Re-run only tests that failed in the prior session |
| diff_base | string | Git branch for patch coverage and failures_in_diff (e.g. main) — use after edits |
| include_flaky | boolean | Include flaky test hints from local history |
| include_missing | boolean | Git-diff scan for source files without matching tests (default true on detect and when diff_base set) |
| timeout_ms | number | Max run time ms (default 1800000 stdio, capped 600000 hosted) |
| detail_level | string | Token budget: brief <500 tokens on PASS; agent default; full=all slices |
| coverage_top | number | Max files in coverage slice |
| limit | number | Max rows for task:history (1–20) |
| inline_files | object | Hosted fallback when github is unavailable: { "package.json": "...", "src/foo.test.ts": "..." }. Supports task detect and task run (temp dir on Railway). Inclu… |
explain_architectureMap how files in the user's project connect — which files are hubs, what imports what, where auth/API/database live. Not file bodies. ALWAYS call when they ask how auth works, where login is checked, what's the database, how the API is wired, give me an overview of these files, or where do I patch…Map how files in the user's project connect — which files are hubs, what imports what, where auth/API/database live. Not file bodies. ALWAYS call when they ask how auth works, where login is checked, what's the database, how the API is wired, give me an overview of these files, or where do I patch…
| Parametro | Tipo | Descrizione |
|---|---|---|
| path | string | The user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder. Hosted with no disk: omit and use inline_files, or a public GitHub… |
| project_path | string | Alias for 'path' (some clients pass this name). Accepts the same values. |
| inline_files | object | Fallback for remote transports. Shape: { "": "" }. Include 10-50 SOURCE files (entry points, routes, middleware, auth, DB setup) plus package.json. For local s… |
| focus | string | Wiring slice. Default: api. auth=validation chain, integrations=external SDK touchpoints, database=ORM, security=auth+errors, full=all analyzers. |
| concern | string | Any subsystem label (folder name, feature codename, module). Uses find_code concept search + import graph — not a fixed keyword list. Returns roles, edges, sym… |
| seed_files | array | 1–20 paths from find_code — graph expands to related modules. Use with or without concern. |
| mode | string | overview=fast wiring map (no AST flow trace), deep=request_flows + sequenceDiagram, audit=anti_patterns + health_score. Default: overview |
| verbosity | string | Output size. minimal=core only, standard=default, full=adds constraints + state_management. Alias: detail_level |
| detail_level | string | Legacy alias for verbosity |
| subpath | string | Monorepo scope — analyze only this subdirectory (e.g. apps/api). Faster than whole repo. |
| force | boolean | Bypass architecture result cache. Default false. |
| exclude | array | Optional glob patterns to exclude from ripgrep (vendor, build, etc.). |
find_codeSearch the user's project when you do not know which file holds something. Ranked hits; the definition of that name comes first, not a call site like const user = await name(). ALWAYS call instead of guessing a path. ALWAYS call when the user says where is, find, who uses, usages, or rename X every…Search the user's project when you do not know which file holds something. Ranked hits; the definition of that name comes first, not a call site like const user = await name(). ALWAYS call instead of guessing a path. ALWAYS call when the user says where is, find, who uses, usages, or rename X every…
| Parametro | Tipo | Descrizione |
|---|---|---|
| query* | string | Required. Text to find: pasted editor line, symbol name (validateToken), or topic keyword (encrypt). |
| path | string | The user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder. Hosted: public GitHub URL or inline_files. |
| intent | string | Search mode. snippet=paste exact line. symbol=find definition. concept=topic hunt. everywhere=all hits before rename. |
| also_try | array | Extra keywords merged in parallel. concept=topic synonyms. everywhere=rename variants (crystal, CRYSTAL, crystal-app). |
| include | string | Limit file types. code=src. docs=md/readme. config=json/yaml. data=sql/prisma. all=default. |
| file_pattern | string | Custom glob; overrides include. Examples: src/**/*.ts, **/*.md. |
| whole_word | boolean | With intent everywhere. true = whole word only (Crystal not Crystalline). Use before renames. |
| case_sensitive | boolean | true = match exact casing (Crystal vs crystal). Default false. |
| inline_files | object | Hosted MCP only: {"path/to/file.ts": "file contents"}. Use when path disk is unavailable. |
| response_format | string | concise=line preview per hit. detailed=full function/class block when AST available. |
get_project_contextAnswer what the user's project is — name, stack, how to run/test/build, auth, database, deploy, folder layout — from their files on disk, not from training data. ALWAYS call this before you invent npm/pip/cargo commands or read package.json yourself. ALWAYS call when the user says: what is this app…Answer what the user's project is — name, stack, how to run/test/build, auth, database, deploy, folder layout — from their files on disk, not from training data. ALWAYS call this before you invent npm/pip/cargo commands or read package.json yourself. ALWAYS call when the user says: what is this app…
| Parametro | Tipo | Descrizione |
|---|---|---|
| path | string | The user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder (any OS). Hosted with no disk: omit and use inline_files. |
| inline_files | object | Primary way to supply code. Shape: { "": "", ... }. The VALUE is the actual file body — never a filename, path, or placeholder. Example: { "package.json": "{"n… |
| force | boolean | Set true to re-detect even if cached (use when project changed) |
| topic | string | Which slice to return (one per call). identity=project name/type + which topics apply; run=dev/test/build/lint commands; framework=language/runtime/package man… |
| detail_level | string | Output tier: "brief" (default, ≤500 tokens), "standard" (full fields), "full" (all fields + file tree) |
| include_structure | boolean | When true, includes file tree in response (also triggered by detail_level: full) |
| structure_depth | number | Max folder depth for file tree scan (default: 3, max: 6) |
| focus_on | string | Subdirectory to focus the file tree scan on (e.g. 'src/tools') |
keep_thinkingStructure multi-step debugging and planning across tool calls — not a one-shot think. Tracks hypotheses, observations, plans; detects loops via lastActions; riskLevel high/critical blocks dangerous edits (drop table, prod deploy). Loads projectBrief (stack, key_paths, project_memory recall) on loca…Structure multi-step debugging and planning across tool calls — not a one-shot think. Tracks hypotheses, observations, plans; detects loops via lastActions; riskLevel high/critical blocks dangerous edits (drop table, prod deploy). Loads projectBrief (stack, key_paths, project_memory recall) on loca…
| Parametro | Tipo | Descrizione |
|---|---|---|
| thought* | string | Reasoning (20–2000 chars) — file names, symbols, error messages. |
| thoughtNumber* | integer | 1-based thought index in this session. |
| totalThoughts* | integer | Estimated thoughts needed (revise upward if needed). |
| nextThoughtNeeded* | boolean | false ends session and writes checkpoint. |
| confidence* | number | 0–1. Below 0.5 forces revision. Above 0.85 safe to proceed. |
| thoughtType* | string | hypothesis|debug for investigation; plan|conclusion before acting. |
| goalAnchor | string | One sentence restating the task — required after thought 2. |
| revises | integer | Thought number this revision replaces. |
| assumptions | array | Up to 5 assumptions; set invalidated:true when contradicted. |
| toolOutputRelevance | string | Classify last tool result — 3+ noise/error in last 5 triggers loop. |
| sessionId | string | Resume prior session; restores checkpoint on thought 1. |
| actionReady | boolean | true when done planning and about to execute edits. |
| lastActions | array | Last 2–5 tool calls as name(arg=val) — identical pair triggers boredLoopDetected. |
| area | string | Subsystem (auth, billing, api) — scopes project_memory recall. |
| projectPath | string | Local project root (stdio defaults to cwd) for projectBrief. |
project_memorySave project notes that must survive this chat — rules, conventions, decisions, gotchas, preferences. Writes notes. Does not read source files. ALWAYS call when they say remember, save this, don't forget, write this down, keep this, my rule, our convention, I always want, last time, what did we dec…Save project notes that must survive this chat — rules, conventions, decisions, gotchas, preferences. Writes notes. Does not read source files. ALWAYS call when they say remember, save this, don't forget, write this down, keep this, my rule, our convention, I always want, last time, what did we dec…
| Parametro | Tipo | Descrizione |
|---|---|---|
| action* | string | remember=save a note, recall=search notes and return full content, list=recent notes with preview, forget=delete by id |
| path | string | Folder these notes belong to. Same string on remember, recall, and list. Stdio: optional (editor cwd). Hosted: reuse that folder string (or normalized_path fro… |
| title | string | Required for remember. Max 80 chars. |
| content | string | Required for remember. Up to 12000 characters (~2000 words). Write the why and the trap — not a one-liner. |
| type | string | Required for remember. decision=chose an approach; gotcha=non-obvious bug; goal=what we are building toward; preference=user style; area_fact=fact about a subs… |
| area | string | Subsystem label (auth, billing, deploy) — included in search index for scoped recall. Max 64 chars. |
| tags | array | Optional lowercase tags. Max 10. |
| written_by | string | Who authored this memory. |
| query | string | Required for recall. Short keywords from the title or topic (e.g. auth middleware stripe). |
| id | string | Required for forget. Memory uuid. |
| limit | number | recall/list cap. Default 10, max 20. |
| scope | string | project=this folder only (default). personal=notes that apply everywhere. all=every project — only when they ask to search everything. |
read_codeRead a known symbol or file from the user's project without dumping the whole tree. AST extract — signature plus body — cheaper than opening a 2,000-line file. ALWAYS call when find_code just returned a name or path, when the user named a function to inspect, or before you edit a large file. If the…Read a known symbol or file from the user's project without dumping the whole tree. AST extract — signature plus body — cheaper than opening a 2,000-line file. ALWAYS call when find_code just returned a name or path, when the user named a function to inspect, or before you edit a large file. If the…
| Parametro | Tipo | Descrizione |
|---|---|---|
| mode | string | symbol=AST extract by name (default). file=batch read files[] (all paths return). outline=file TOC. scan=keyword/pattern hits across files[] (use target or tar… |
| path | string | The user's project folder. Local/stdio: omit to use editor cwd, or pass the absolute folder. Hosted with no disk: use inline_files. Pair files[] from find_code. |
| inline_files | object | When path disk is unavailable: {"src/auth.ts": ""}. Hosted/private transport fallback. |
| target | string | mode:symbol|callers|blast_radius — symbol name (fuzzy). mode:scan — keyword or regex to find across files[]. |
| symbol_id | string | With mode:symbol. Direct lookup ID from a prior hit (e.g. src/auth.ts::validateUser#function). Skips fuzzy search. |
| targets | array | mode:symbol — batch symbol names (max 8, set max_results:10). mode:scan — multiple keywords in one pass across files[]. |
| files | array | With mode:file|outline. Relative paths — from find_code hits. File mode: every path returns in one call (truncated per file if large, never dropped). |
| offset_line | number | With mode:file. Start line (1-indexed). Use after batch read when data.hint says truncated. |
| limit_lines | number | With mode:file. Max lines per file. Default: budget-based; set for pagination slices. |
| compact | boolean | With mode:file|symbol. true = omit line numbers to save tokens. |
| kind | string | With mode:symbol. Filter to one symbol kind — disambiguate class vs method with same name. |
| context_path | string | With mode:symbol. File path hint for ranking (e.g. src/auth.ts when repo has many auth symbols). |
| detail_level | string | With mode:symbol. signature=~100 tokens. body=full implementation (default). context=body+imports. |
| max_tokens | number | Response size cap (default 2000, max 8000). File batch auto-shares across paths. Lower only if context is tight. |
| max_results | number | mode:symbol — max symbols (default 3, max 10). mode:scan|smell — max hits returned (default 30, max 100). |
| confidence_threshold | number | With mode:symbol. Min match confidence 0–1 (default 0.5). Raise 0.8 for exact; lower 0.3 to explore. |
| session_id | string | Dedup across turns — symbols already returned get a stub with symbol_id instead of full body. |
Zephex_dev_infoExpert developer playbooks — not your repo. Stripe webhooks & checkout, Supabase RLS, Next.js auth (clerk, next-auth), payment flows, CSP/HSTS, deploy patterns. operation=search finds entries by question; operation=get returns full guidance by slug from search. Read summary and checklist first. 2 c…Expert developer playbooks — not your repo. Stripe webhooks & checkout, Supabase RLS, Next.js auth (clerk, next-auth), payment flows, CSP/HSTS, deploy patterns. operation=search finds entries by question; operation=get returns full guidance by slug from search. Read summary and checklist first. 2 c…
| Parametro | Tipo | Descrizione |
|---|---|---|
| operation | string | search=find by query (first step); get=full entry by slug from search. |
| query | string | Required for search — e.g. 'Supabase RLS for multi-tenant' or 'Next.js middleware auth'. |
| slug | string | Required for get — exact slug from a search hit. |
| category | string | Optional search filter — payments, auth, security, databases, etc. |
10 strumenti su 10 hanno pubblicato una descrizione.
I nomi e le descrizioni degli strumenti sono scritti dal publisher e mostrati alla lettera come testo inerte. Sono le stringhe che un client MCP passa a un modello, quindi Forge vi cerca schemi di prompt injection — ogni rilievo compare insieme all’analisi di sicurezza qui sopra. «Privilegiato» è una corrispondenza di parola chiave sul nome dello strumento, non una verifica di ciò che fa: un nome innocuo può comunque fare qualsiasi cosa.
MCP gateway with 10 tools for code analysis, architecture, package audit & security.
I nomi collegati aprono l’indice Forge di tutte le voci osservate esporre quello strumento. Sfoglia tutti gli strumenti indicizzati.
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.